Interworking Handover Encryption Policy for EPS to 5GS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the interworking handover from EPS to 5GS, the source system does not provide a user plane encryption policy to the target network node, leading to incomplete security configurations during handover processes.
Innovation Solution
A method where a user plane encryption policy is explicitly provided to the target radio access network node, set to 'required', 'preferred', or 'not needed', by the source network node during the handover process, ensuring consistent security settings across systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the source system provides only user plane integrity protection policy to the target network node during handover, then the handover process follows existing protocols, but the security configuration is incomplete without encryption policy
Solution Approach 1:
The source network node determines and includes the user plane encryption policy in the handover request message before the handover occurs. This preliminary action ensures that the target network node receives complete security configuration information (both integrity protection policy and encryption policy) in advance, eliminating the need for additional security configuration steps after handover and ensuring complete security configuration without significantly increasing message complexity
Solution Approach 2:
The patent combines the user plane integrity protection policy and user plane encryption policy into a single handover request message. By merging these two security policy elements into one message structure, the patent achieves complete security configuration transmission while avoiding the need for separate additional signaling messages, thus resolving the contradiction between security completeness and message structure complexity
2Stability of the object's composition
If the source network node determines encryption policy based on local configuration for each radio bearer, then security policy consistency is achieved, but the processing overhead increases
Solution Approach 1:
The source network node changes the parameter of security policy determination from a generic system-wide policy to specific per-radio-bearer policies based on local configuration. By evaluating and setting encryption policies individually for each radio bearer (with options: required, preferred, not needed), the patent achieves consistent security policy application across different bearers while the local configuration approach actually reduces processing overhead compared to centralized policy determination for each bearer
Data Source
AI summary
A method performed by a target network node for interworking handover from an evolved packet system, EPS, to a fifth generation system, 5GS, in a mobile network is provided. The method includes receiving, from a source network node, a determined user plane, UP, encryption policy. The method further includes providing the determined UP encryption policy to a target radio access network node. Corresponding embodiments for methods performed by a source network node and a first target network node are also provided.


